Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-79
Total 21765 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-25295 1 Opencats 1 Opencats 2021-01-26 4.3 MEDIUM 6.1 MEDIUM
OpenCATS through 0.9.5-3 has multiple Cross-site Scripting (XSS) issues.
CVE-2010-3906 2 Git, Git-scm 2 Git, Git 2021-01-26 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) f and (2) fp parameters.
CVE-2017-1000488 2 Acquia, Mautic 2 Mautic, Mautic 2021-01-25 4.3 MEDIUM 6.1 MEDIUM
Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-populate the form.
CVE-2018-11198 1 Acquia 1 Mautic 2021-01-25 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Mautic 2.13.1. There is Stored XSS via the authorUrl field in config.json.
CVE-2020-15864 1 Quali 1 Cloudshell 2021-01-22 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in Quali CloudShell 9.3. An XSS vulnerability in the login page allows an attacker to craft a URL, with a constructor.constructor substring in the username field, that executes a payload when the user visits the /Account/Login page.
CVE-2020-13134 1 Tufin 1 Securechange 2021-01-22 3.5 LOW 4.8 MEDIUM
Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires admin privileges (for storing the XSS payload itself), and can exploit (be triggered by) admin users. All TOS versions with SecureChange deployments prior to R19.3 HF3 and R20-1 HF1 are affected. Vulnerabilities were fixed in R19.3 HF3 and R20-1 HF1.
CVE-2020-13133 1 Tufin 1 Securechange 2021-01-22 4.3 MEDIUM 6.1 MEDIUM
Tufin SecureChange prior to R19.3 HF3 and R20-1 HF1 are vulnerable to stored XSS. The successful exploitation requires admin privileges (for storing the XSS payload itself), and can exploit (be triggered by) unauthenticated users. All TOS versions with SecureChange deployments prior to R19.3 HF3 and R20-1 HF1 are affected. Vulnerabilities were fixed in R19.3 HF3 and R20-1 HF1
CVE-2020-28707 1 Stockdio 1 Stockdio Historical Chart 2021-01-22 4.3 MEDIUM 6.1 MEDIUM
The Stockdio Historical Chart plugin before 2.8.1 for WordPress is affected by Cross Site Scripting (XSS) via stockdio_chart_historical-wp.js in wp-content/plugins/stockdio-historical-chart/assets/ because the origin of a postMessage() event is not validated. The stockdio_eventer function listens for any postMessage event. After a message event is sent to the application, this function sets the "e" variable as the event and checks that the types of the data and data.method are not undefined (empty) before proceeding to eval the data.method received from the postMessage. However, on a different website. JavaScript code can call window.open for the vulnerable WordPress instance and do a postMessage(msg,'*') for that object.
CVE-2020-19362 1 Vtiger 1 Vtiger Crm 2021-01-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page.
CVE-2021-20619 1 Weseek 1 Growi 2021-01-22 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in GROWI (v4.2 Series) versions prior to v4.2.3 allows remote attackers to inject an arbitrary script via unspecified vectors.
CVE-2020-19361 1 Medintux 1 Medintux 2021-01-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in Medintux v2.16.000 CCAM.php by manipulating the mot1 parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page.
CVE-2021-3137 1 Xwiki 1 Xwiki 2021-01-22 3.5 LOW 5.4 MEDIUM
XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.
CVE-2021-23838 1 Flatcore 1 Flatcore 2021-01-22 3.5 LOW 4.8 MEDIUM
An issue was discovered in flatCore before 2.0.0 build 139. A reflected XSS vulnerability was identified in the media_filter HTTP request body parameter for the acp interface. The affected parameter accepts malicious client-side script without proper input sanitization. For example, a malicious user can leverage this vulnerability to steal cookies from a victim user and perform a session-hijacking attack, which may then lead to unauthorized access to the site.
CVE-2021-23836 1 Flatcore 1 Flatcore 2021-01-22 3.5 LOW 4.8 MEDIUM
An issue was discovered in flatCore before 2.0.0 build 139. A stored XSS vulnerability was identified in the prefs_smtp_psw HTTP request body parameter for the acp interface. An admin user can inject malicious client-side script into the affected parameter without any form of input sanitization. The injected payload will be executed in the browser of a user whenever one visits the affected module page.
CVE-2020-25385 1 Nagios 1 Log Server 2021-01-22 4.3 MEDIUM 6.1 MEDIUM
Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapshot through the snapshot_name parameter, which may impact users who open a maliciously crafted link or third-party web page.
CVE-2020-27851 1 Rocketgenius 1 Gravityforms 2021-01-21 3.5 LOW 5.4 MEDIUM
Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary HTML code via poll or quiz answers. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).
CVE-2020-27852 1 Rocketgenius 1 Gravityforms 2021-01-21 3.5 LOW 5.4 MEDIUM
A stored Cross-Site Scripting (XSS) vulnerability in the survey feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via a textarea field. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).
CVE-2020-27850 1 Rocketgenius 1 Gravityforms 2021-01-21 3.5 LOW 4.8 MEDIUM
A stored Cross-Site Scripting (XSS) vulnerability in forms import feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via the import of a GF form. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).
CVE-2021-25324 1 Misp 1 Misp 2021-01-21 4.3 MEDIUM 6.1 MEDIUM
MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.
CVE-2021-3184 1 Misp 1 Misp 2021-01-21 4.3 MEDIUM 6.1 MEDIUM
MISP 2.4.136 has XSS via a crafted URL to the app/View/Elements/global_menu.ctp user homepage favourite button.